Earlier quoted context omitted.
Nah, middleboxes are garbage. The security features they claim to offer are all snakeoil checkbox-ware, businesses and government agencies/state-controlled telcos use them because they have a nominal compliance obligation to do a thing so they buy a middlebox that they can wave their arms at when the auditor/commissar comes around. Generalized "optimizer" middleboxes don't actually work in real world performance test…
I'll give you that a lot of the middlebox problems are because they are garbage, however... Dismissing the security features they are ostensibly delivering snakeoil is more than a bit unfair. There is a legit security context where absolute transparency & auditability is the right design objective, rather than absolute privacy. I'd argue the greatest failing we've seen with the evolution of TLS was the failure to rec…
Transparency and Auditability are real, but they absolutely require endpoint security.
If you don't control the endpoint you don't know if it has an LTE chip, and if you do control the endpoint you don't care.
DPI security middleboxes for the enterprise are always and without exception snakeoil and/or checkboxware.